tcp 22 > tcp 22

Nikolaj I. Potanin nikolaj at drweb.ru
Wed Jul 2 00:19:35 PDT 2003


> Jul  1 13:34:35 fbsd /kernel: ipfw: 1400 Accept TCP xxxxxx:22 yyyyy:22 in via
> ed1
> where xxxxxx is the attacker's IP and yyyyy is my box.
> Also, as you can see, the connection is made from port 22 to port 22, which is
> odd.

http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=22441 -
maybe this could explain your case?

-- 
Nikolaj I. Potanin, SA                          http://www.drweb.ru
ID Anti-Virus Lab (SalD Ltd)                    nikolaj at drweb.ru
St. Petersburg, Russia                          ph.: +7-812-3888624



More information about the freebsd-security mailing list